漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
MISP organisation logo path traversal allows retrieval of arbitrary PNG/SVG files
Vulnerability Description
MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisation logo file paths using organisation-controlled fields such as id, name, and uuid without ensuring that the resolved file remains inside the intended APP/files/img/orgs/ directory. An attacker able to influence an organisation field, for example the organisation name, could use path traversal sequences to cause MISP to return arbitrary readable .png or .svg files from outside the organisation logo directory. The issue is fixed by resolving candidate paths with realpath() and verifying that they remain under the expected base directory before serving the file.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/U:Green
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
MISP 路径遍历漏洞
Vulnerability Description
MISP是MISP组织开源的一套开源的软件解决方案。 该产品用于收集、存储、分发、共享网络安全指标,并具有威胁网络安全事件分析和恶意软件分析等功能。 MISP 2.5.40之前版本存在路径遍历漏洞,该漏洞源于OrganisationsController::getOrgLogo中的路径遍历问题,使用组织控制字段(如id、name和uuid)构建组织徽标文件路径,未确保解析文件保持在APP/files/img/orgs/目录内,可能允许攻击者影响组织字段,利用路径遍历序列读取任意.png或.svg文件。
CVSS Information
N/A
Vulnerability Type
N/A